How a Fake Invoice Gets Paid
Business email compromise works by inserting one plausible instruction into a real conversation. The attacker gains access to or convincingly imitates a supplier's mailbox, waits for an invoice cycle, and sends updated bank details at the moment a payment is already expected. Nothing about the request looks unusual, because the timing is genuine.
That is why this fraud defeats controls built to catch unusual activity. The supplier is real, the invoice amount matches the purchase order, the email thread has months of history above it, and the only altered element is a sort code. The material to leave in the source document is any real supplier detail: names, account numbers, and reproductions of genuine invoices must be replaced with fabricated examples, because a training video showing a real payment instruction is itself a document worth stealing.
The template walks the fraud through eight scenes: two on how the attacker gets inside the conversation, one on the timing that makes the request look normal, one on the urgency and confidentiality pressure applied to the approver, two on the out-of-band verification that stops it, one on the approval limits that contain it, and one on what to do in the first hour after a suspect payment.

